1. Scope and responsibilities
Faraday is the service provider identified in your signed agreement. This policy covers website visitors, business contacts, service users, and personal information in connected business records. When Faraday handles information on behalf of an organization, that organization's instructions and applicable data-processing agreement also govern that processing.
For information controlled by your employer or another customer organization, contact that organization first. Faraday can help route a request to the appropriate account owner.
2. Information involved
Information may include names, business email addresses, organization details, account information, support correspondence, submitted documents, and information provided through website forms.
Depending on the integrations you authorize, connected data may include customer and supplier records, orders, invoices, products, inventory, purchase orders, CRM activity, and financial records. These records can contain personal information. The actual fields depend on provider permissions and the agreed workflow.
Service operation may involve authentication tokens, session identifiers, IP addresses, device or browser information, request timestamps, diagnostic events, and audit records. Do not submit passwords or API secrets through ordinary contact forms.
3. How information is used
Faraday uses information to provide authorized services, authenticate users, operate integrations, produce requested analyses, answer inquiries, provide support, investigate problems, maintain security, and meet contractual or legal obligations.
For connected Intuit QuickBooks data, the purposes and scope are limited by the authorized integration, the customer agreement, applicable law, and Intuit's requirements. Connecting an account does not authorize unrelated use of its data.
4. Service providers and disclosures
Delivering a configured service may involve hosting, database, storage, email, identity, monitoring, or AI-model providers. Information may be disclosed to those providers as needed for the agreed service, and to users authorized by the customer organization.
AI-enabled workflows may send selected inputs to the configured model provider. The applicable agreement and workflow configuration must establish what is sent and the provider's processing and retention terms. Do not assume model-provider access, retention, or training settings are identical across deployments.
Information may also be disclosed where required by law, to address security or legal claims, or in connection with a business transaction subject to applicable safeguards. Contact Faraday for the providers and data-processing terms applicable to your deployment.
6. Retention, disconnection, and deletion
Retention depends on the purpose of processing, customer instructions, the applicable agreement, security requirements, and legal obligations. Backup and audit-record handling may differ from active application records. Ask Faraday for the retention and deletion schedule applicable to your deployment.
You can revoke a connection in the third-party service or request disconnection assistance. Disconnection is separate from deletion of previously imported data. Submit a deletion or export request through your organization's administrator or the contact below; identity and authority may need to be verified.
7. Security and processing locations
Security responsibilities and safeguards are defined by the service configuration and applicable agreements. No internet service can guarantee absolute security. Report suspected unauthorized access promptly, without including credentials in your message.
Providers may process information in countries other than your own. Applicable agreements should identify processing locations and required transfer safeguards; contact Faraday for deployment-specific details.
8. Your choices and requests
Depending on applicable law, you may have rights to access, correct, delete, or obtain a copy of personal information, object to or restrict processing, or withdraw consent. Some requests may be subject to legal exceptions or the instructions of the customer organization controlling the data.
Contact Faraday using the address below, identify your organization and request, and avoid sending sensitive records unnecessarily. You may also have a right to raise a concern with the relevant data-protection authority. The services are intended for business users, not children.
9. Changes and contact
Updates to this policy will be published with an effective date. Material changes will be communicated as required by applicable law and customer agreements. Direct privacy questions and requests to the Faraday team at the address below.